Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 43 vulnerabilities #121

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

karencapiiro
Copy link

snyk-top-banner

Snyk has created this PR to fix 43 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • scripts/bench/package.json
  • scripts/bench/yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542721
  457  
high severity Improper Link Resolution Before File Access
SNYK-JS-NODEGIT-542723
  453  
high severity Code Injection
SNYK-JS-LODASH-1040724
  239  
high severity Command Injection
SNYK-JS-CHROMELAUNCHER-537575
  238  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-174125
  238  
critical severity Authentication Bypass
SNYK-JS-HAWK-6969142
  212  
medium severity Uninitialized Memory Exposure
npm:stringstream:20180511
  202  
high severity Improper Handling of Alternate Data Stream
SNYK-JS-NODEGIT-542722
  199  
high severity Directory Traversal
SNYK-JS-NODEGIT-542720
  198  
high severity Prototype Pollution
SNYK-JS-LODASH-567746
  189  
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
  188  
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
  170  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  169  
high severity Prototype Pollution
SNYK-JS-AJV-584908
  165  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  159  
high severity Denial of Service (DoS)
SNYK-JS-ECSTATIC-540354
  159  
high severity Denial of Service (DoS)
SNYK-JS-JPEGJS-2859218
  159  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  159  
high severity Prototype Pollution
SNYK-JS-LODASH-450202
  152  
high severity Prototype Pollution
SNYK-JS-INI-1048974
  151  
high severity Prototype Pollution
SNYK-JS-LODASH-608086
  150  
high severity Prototype Pollution
SNYK-JS-LODASH-73638
  149  
high severity Prototype Pollution
npm:deep-extend:20180409
  149  
medium severity Prototype Pollution
npm:hoek:20180212
  141  
medium severity Prototype Pollution
SNYK-JS-DOTPROP-543489
  140  
medium severity Prototype Pollution
npm:lodash:20180130
  140  
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
  137  
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
  137  
medium severity Denial of Service (DoS)
SNYK-JS-HTTPPROXY-569139
  134  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
  133  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  131  
high severity Prototype Override Protection Bypass
npm:qs:20170213
  114  
high severity Arbitrary File Overwrite
SNYK-JS-FSTREAM-174725
  107  
high severity Prototype Pollution
npm:extend:20180424
  107  
medium severity Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
  102  
medium severity Denial of Service (DoS)
SNYK-JS-JPEGJS-570039
  101  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
  97  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
  63  
medium severity Open Redirect
SNYK-JS-GOT-2932019
  61  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  60  
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
  58  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  45  
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
  44  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Command Injection
🦉 More lessons are available in Snyk Learn

…ulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-NODEGIT-542721
- https://snyk.io/vuln/SNYK-JS-NODEGIT-542723
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://snyk.io/vuln/SNYK-JS-CHROMELAUNCHER-537575
- https://snyk.io/vuln/SNYK-JS-TAR-174125
- https://snyk.io/vuln/SNYK-JS-HAWK-6969142
- https://snyk.io/vuln/npm:stringstream:20180511
- https://snyk.io/vuln/SNYK-JS-NODEGIT-542722
- https://snyk.io/vuln/SNYK-JS-NODEGIT-542720
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
- https://snyk.io/vuln/SNYK-JS-Y18N-1021887
- https://snyk.io/vuln/SNYK-JS-LODASH-6139239
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://snyk.io/vuln/SNYK-JS-AJV-584908
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-ECSTATIC-540354
- https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-INI-1048974
- https://snyk.io/vuln/SNYK-JS-LODASH-608086
- https://snyk.io/vuln/SNYK-JS-LODASH-73638
- https://snyk.io/vuln/npm:deep-extend:20180409
- https://snyk.io/vuln/npm:hoek:20180212
- https://snyk.io/vuln/SNYK-JS-DOTPROP-543489
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
- https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
- https://snyk.io/vuln/SNYK-JS-HTTPPROXY-569139
- https://snyk.io/vuln/SNYK-JS-LODASH-73639
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
- https://snyk.io/vuln/npm:qs:20170213
- https://snyk.io/vuln/SNYK-JS-FSTREAM-174725
- https://snyk.io/vuln/npm:extend:20180424
- https://snyk.io/vuln/npm:tough-cookie:20170905
- https://snyk.io/vuln/SNYK-JS-JPEGJS-570039
- https://snyk.io/vuln/SNYK-JS-HAWK-2808852
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JS-GOT-2932019
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-COOKIE-8163060
@rafikmojr
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Detailsace21688-5667-48ee-afcd-d0cb23dc9586

New Issues

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2023-4860 Npm-electron-23.1.2 Vulnerable Package
CRITICAL CVE-2024-40643 Npm-htmlparser2-3.10.1 Vulnerable Package
CRITICAL CVE-2024-40643 Npm-htmlparser2-3.3.0 Vulnerable Package
CRITICAL CVE-2024-42461 Npm-elliptic-6.5.4 Vulnerable Package
CRITICAL CVE-2024-42461 Npm-elliptic-6.5.3 Vulnerable Package
CRITICAL CVE-2024-42461 Npm-elliptic-6.4.0 Vulnerable Package
CRITICAL CVE-2024-4559 Npm-electron-23.1.2 Vulnerable Package
CRITICAL CVE-2024-4671 Npm-electron-23.1.2 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.5.3 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.5.4 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.4.0 Vulnerable Package
CRITICAL CVE-2024-7024 Npm-electron-23.1.2 Vulnerable Package
CRITICAL CVE-2024-9370 Npm-electron-23.1.2 Vulnerable Package
CRITICAL CVE-2024-9963 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2022-21213 Npm-mout-1.1.0 Vulnerable Package
HIGH CVE-2022-25858 Npm-terser-4.8.0 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.2.3 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.6 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.3 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.21 Vulnerable Package
HIGH CVE-2023-7010 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2023-7012 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10229 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10230 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10231 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10487 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10488 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10826 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-10827 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-11112 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-11113 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-11114 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-11115 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-11395 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-12053 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-1674 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-0.17.3 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-2.0.6 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-0.17.4 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-6.0.5 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-7.0.1 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-5.1.0 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-4.0.2 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-7.0.3 Vulnerable Package
HIGH CVE-2024-2176 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-29415 Npm-ip-1.1.5 Vulnerable Package
HIGH CVE-2024-3156 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3158 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3159 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3168 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3169 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3170 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3171 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3172 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3173 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3174 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3176 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.2.3 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.5.9 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.2.1 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-8.13.0 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-8.12.0 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.5.5 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-6.2.2 Vulnerable Package
HIGH CVE-2024-3832 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3834 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3837 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-3914 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4058 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4059 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4060 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-2.3.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-3.0.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-1.8.5 Vulnerable Package
HIGH CVE-2024-4331 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4368 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-0.1.7 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-1.8.0 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-1.7.0 Vulnerable Package
HIGH CVE-2024-4558 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.19.0 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.19.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.20.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.18.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.20.1 Vulnerable Package
HIGH CVE-2024-4761 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4947 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4948 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-4950 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5157 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5158 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5159 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5160 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5274 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5493 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5494 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5495 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5496 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5497 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5498 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5499 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5830 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5831 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5832 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5833 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5834 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5835 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5836 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5837 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5838 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5841 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5842 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5844 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5845 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5846 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-5847 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6100 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6101 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6102 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6103 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6290 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6291 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6292 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6293 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6772 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6773 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6774 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6775 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6776 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6777 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6778 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6779 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6988 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6989 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6990 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6991 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6994 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6997 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-6998 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7000 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7018 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7022 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7023 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7025 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7255 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7256 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7532 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7533 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7534 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7535 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7536 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7550 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7964 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7965 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7966 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7967 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7968 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7969 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7970 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7971 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7972 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7973 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7974 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7977 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7979 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-7980 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8193 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8194 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8198 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8362 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8636 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8637 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8638 Npm-electron-23.1.2 Vulnerable Package
HIGH CVE-2024-8639 Npm-electron-23.1.2

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants